i am currently trying to build an alert, which will be triggered if a message has just existed and already existed 10 minutes ago.
message: “Test” -> true & message: “Test” (10 minutes ago) -> true ==> Trigger alert
Does anyone of you know a solution to this problem?
that is what the correlation feature is given for.
Thanks for the quick answer.
I am currently using Graylog Open Source, so there is no way to use any workaround for this feature?
If you are ingesting less than 5G a day, you can apply for a free enterprise license.
This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.